5
CVSSv2

CVE-2005-2109

Published: 05/07/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

wp-login.php in WordPress 1.5.1.2 and previous versions allows remote malicious users to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 1.0

wordpress wordpress 1.0.1

wordpress wordpress 1.0.2

wordpress wordpress 1.5.1

wordpress wordpress 1.5.1.2

wordpress wordpress 1.2

wordpress wordpress 1.5